This page lists the IAM roles and permissions for Service Networking. To search through all roles and permissions, see the role and permission index .
Service Networking roles
Servicenetworking Admin Beta
( roles/
)
Admin role for servicenetworking
resourcemanager.projects.get
resourcemanager.projects.list
servicenetworking.*
-
servicenetworking.operations. cancel -
servicenetworking.operations. delete -
servicenetworking.operations. get -
servicenetworking.operations. list -
servicenetworking.services. addDnsRecordSet -
servicenetworking.services. addDnsZone -
servicenetworking.services. addPeering -
servicenetworking.services. addSubnetwork -
servicenetworking.services. createPeeredDnsDomain -
servicenetworking.services. deleteConnection -
servicenetworking.services. deletePeeredDnsDomain -
servicenetworking.services. disableVpcServiceControls -
servicenetworking.services. enableVpcServiceControls -
servicenetworking.services.get -
servicenetworking.services. getConsumerConfig -
servicenetworking.services. getVpcServiceControls -
servicenetworking.services. listPeeredDnsDomains -
servicenetworking.services. removeDnsRecordSet -
servicenetworking.services. removeDnsZone -
servicenetworking.services. updateConsumerConfig -
servicenetworking.services. updateDnsRecordSet -
servicenetworking.services.use
Servicenetworking Editor Beta
( roles/
)
Editor role for servicenetworking
resourcemanager.projects.get
resourcemanager.projects.list
servicenetworking.operations.*
-
servicenetworking.operations. cancel -
servicenetworking.operations. delete -
servicenetworking.operations. get -
servicenetworking.operations. list
servicenetworking.
servicenetworking.
servicenetworking.
servicenetworking.
servicenetworking.
servicenetworking.
servicenetworking.
servicenetworking.
servicenetworking.services.get
servicenetworking.
servicenetworking.
servicenetworking.
servicenetworking.
servicenetworking.
servicenetworking.
servicenetworking.
servicenetworking.services.use
Servicenetworking Viewer Beta
( roles/
)
Viewer role for servicenetworking
resourcemanager.projects.get
resourcemanager.projects.list
servicenetworking.
servicenetworking.
servicenetworking.services.get
servicenetworking.
servicenetworking.
servicenetworking.
servicenetworking.services.use
Service Networking Admin Beta
( roles/
)
Full control of service networking with projects.
servicenetworking.*
-
servicenetworking.operations. cancel -
servicenetworking.operations. delete -
servicenetworking.operations. get -
servicenetworking.operations. list -
servicenetworking.services. addDnsRecordSet -
servicenetworking.services. addDnsZone -
servicenetworking.services. addPeering -
servicenetworking.services. addSubnetwork -
servicenetworking.services. createPeeredDnsDomain -
servicenetworking.services. deleteConnection -
servicenetworking.services. deletePeeredDnsDomain -
servicenetworking.services. disableVpcServiceControls -
servicenetworking.services. enableVpcServiceControls -
servicenetworking.services.get -
servicenetworking.services. getConsumerConfig -
servicenetworking.services. getVpcServiceControls -
servicenetworking.services. listPeeredDnsDomains -
servicenetworking.services. removeDnsRecordSet -
servicenetworking.services. removeDnsZone -
servicenetworking.services. updateConsumerConfig -
servicenetworking.services. updateDnsRecordSet -
servicenetworking.services.use
Service agent roles
Service agent roles should only be granted to service agents .
Service Networking Service Agent
( roles/
)
Gives permission to manage network configuration, such as establishing network peering, necessary for service producers
compute.globalAddresses.get
compute.globalAddresses.list
compute.globalOperations.get
compute.networks.addPeering
compute.networks.create
compute.networks.delete
compute.networks.get
compute.networks.list
compute.
compute.networks.removePeering
compute.networks.update
compute.networks.updatePeering
compute.networks.updatePolicy
compute.projects.get
compute.regionOperations.get
compute.routers.get
compute.routers.list
compute.routes.list
compute.subnetworks.create
compute.subnetworks.delete
compute.subnetworks.get
compute.subnetworks.list
dns.changes.*
-
dns.changes.create -
dns.changes.get -
dns.changes.list
dns.dnsKeys.*
-
dns.dnsKeys.get -
dns.dnsKeys.list
dns.gkeClusters.*
-
dns.gkeClusters. bindDNSResponsePolicy -
dns.gkeClusters. bindPrivateDNSZone
dns.managedZoneOperations.*
-
dns.managedZoneOperations.get -
dns.managedZoneOperations.list
dns.managedZones.create
dns.managedZones.delete
dns.managedZones.get
dns.managedZones.getIamPolicy
dns.managedZones.list
dns.managedZones.update
dns.networks.*
-
dns.networks. bindDNSResponsePolicy -
dns.networks. bindPrivateDNSPolicy -
dns.networks. bindPrivateDNSZone -
dns.networks. targetWithPeeringZone -
dns.networks.useHealthSignals
dns.policies.create
dns.policies.delete
dns.policies.get
dns.policies.list
dns.policies.listEffectiveTags
dns.policies.listTagBindings
dns.policies.update
dns.projects.get
dns.resourceRecordSets.*
-
dns.resourceRecordSets.create -
dns.resourceRecordSets.delete -
dns.resourceRecordSets.get -
dns.resourceRecordSets.list -
dns.resourceRecordSets.update
dns.responsePolicies.*
-
dns.responsePolicies.create -
dns.responsePolicies.delete -
dns.responsePolicies.get -
dns.responsePolicies.list -
dns.responsePolicies.update
dns.responsePolicyRules.*
-
dns.responsePolicyRules.create -
dns.responsePolicyRules.delete -
dns.responsePolicyRules.get -
dns.responsePolicyRules.list -
dns.responsePolicyRules.update
networkconnectivity.
resourcemanager.projects.get
resourcemanager.projects.list
Service Networking permissions
servicenetworking.
operations.
cancel
Owner
( roles/
)
Editor
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Service Networking Admin
( roles/
)
servicenetworking.
operations.
delete
Owner
( roles/
)
Editor
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Service Networking Admin
( roles/
)
servicenetworking.
operations.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compute Network Admin
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Servicenetworking Viewer
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
Service Networking Admin
( roles/
)
Service agent roles
- Cloud Deployment Manager Service Agent
(
roles/)clouddeploymentmanager.serviceAgent - Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cluster Director Service Agent
(
roles/)hypercomputecluster.serviceAgent
servicenetworking.
operations.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Servicenetworking Viewer
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Service Networking Admin
( roles/
)
servicenetworking.
services.
addDnsRecordSet
Owner
( roles/
)
Editor
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Service Networking Admin
( roles/
)
servicenetworking.
services.
addDnsZone
Owner
( roles/
)
Editor
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Service Networking Admin
( roles/
)
servicenetworking.
services.
addPeering
Owner
( roles/
)
Compute Network Admin
( roles/
)
Servicenetworking Admin
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Service Networking Admin
( roles/
)
Service agent roles
- Cloud Deployment Manager Service Agent
(
roles/)clouddeploymentmanager.serviceAgent - Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cluster Director Service Agent
(
roles/)hypercomputecluster.serviceAgent
servicenetworking.
services.
addSubnetwork
Owner
( roles/
)
Editor
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Service Networking Admin
( roles/
)
servicenetworking.
services.
createPeeredDnsDomain
Owner
( roles/
)
Editor
( roles/
)
Compute Network Admin
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Service Networking Admin
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent
servicenetworking.
services.
deleteConnection
Owner
( roles/
)
Editor
( roles/
)
Compute Network Admin
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Service Networking Admin
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cluster Director Service Agent
(
roles/)hypercomputecluster.serviceAgent
servicenetworking.
services.
deletePeeredDnsDomain
Owner
( roles/
)
Editor
( roles/
)
Compute Network Admin
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Service Networking Admin
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cluster Director Service Agent
(
roles/)hypercomputecluster.serviceAgent
servicenetworking.
services.
disableVpcServiceControls
Owner
( roles/
)
Editor
( roles/
)
Compute Network Admin
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Service Networking Admin
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent
servicenetworking.
services.
enableVpcServiceControls
Owner
( roles/
)
Editor
( roles/
)
Compute Network Admin
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Service Networking Admin
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent
servicenetworking.services.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compute Network Admin
( roles/
)
Compute Network User
( roles/
)
Compute Network Viewer
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Servicenetworking Viewer
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Service Networking Admin
( roles/
)
Service agent roles
- Cloud Deployment Manager Service Agent
(
roles/)clouddeploymentmanager.serviceAgent - Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Data Fusion API Service Agent
(
roles/)datafusion.serviceAgent - Cluster Director Service Agent
(
roles/)hypercomputecluster.serviceAgent - Cluster Director Shared VPC Service Agent
(
roles/)hypercomputecluster.sharedVpcServiceAgent
servicenetworking.
services.
getConsumerConfig
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Servicenetworking Viewer
( roles/
)
Support User
( roles/
)
Service Networking Admin
( roles/
)
servicenetworking.
services.
getVpcServiceControls
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compute Network Admin
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Servicenetworking Viewer
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
Service Networking Admin
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent
servicenetworking.
services.
listPeeredDnsDomains
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compute Network Admin
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Servicenetworking Viewer
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
Service Networking Admin
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cluster Director Service Agent
(
roles/)hypercomputecluster.serviceAgent
servicenetworking.
services.
removeDnsRecordSet
Owner
( roles/
)
Editor
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Service Networking Admin
( roles/
)
servicenetworking.
services.
removeDnsZone
Owner
( roles/
)
Editor
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Service Networking Admin
( roles/
)
servicenetworking.
services.
updateConsumerConfig
Owner
( roles/
)
Editor
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Service Networking Admin
( roles/
)
servicenetworking.
services.
updateDnsRecordSet
Owner
( roles/
)
Editor
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Service Networking Admin
( roles/
)
servicenetworking.services.use
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Servicenetworking Viewer
( roles/
)
Support User
( roles/
)
Service Networking Admin
( roles/
)

